Watch And Earn docs
v4.0.0
Live demoConsole demo Get help
● Cash wallet · Protect your money

Fraud signals and limits
flags, never silent rejections.

Every payout request is checked against limits that refuse it and fraud signals that flag it. Flags never reject a request on their own: they make it wait for a person and show you why.

requestPayoutreview.flagsHeuristics, not proof

01What refuses a request

requestPayout refuses a request with a reason token the app translates (docs/CONTRACT-4.0.md §11.3, firebase/functions/src/wallet/payouts.ts):

ReasonWhy
disabled, method_offThe wallet or that method is switched off
platformThe wallet is off on the user's platform (iOS and web by default)
countryThe method or gift card is limited to other countries
bad_email, bad_asset, bad_address, missing_bank_field, bad_iban, bad_giftcard, bad_face_value, amount_mismatchThe destination does not pass the checks of that method
below_minBelow the method's minimum, or the fee is as large as the amount
insufficient_fundsMore than the available balance
account_ageAccount younger than wallet.minAccountAgeDays (default 3)
email_unverifiedNot signed in with Google or Apple and no verified e-mail, while wallet.requireVerifiedEmail is on (default)
negative_balanceA reversal made the available balance negative
daily_limit, monthly_limitOver the per-user limit for the UTC day or month (pending, approved, processing and paid requests count)
banned, frozenThe user is banned, or you froze their payouts on the Wallets page
rate_limitedMore than 3 requests in an hour

Troubleshooting for each: Payouts.

02Fraud flags on a request

A request that passes is checked once more and gets a list of flags (review.flags, fraudFlags() in firebase/functions/src/wallet/money.ts). The Payouts page shows them as pills.

FlagRaised whenWhat to check
shared_deviceThe user's device has more accounts than Anti-fraud → Accounts per deviceThe other accounts in the drawer; one person farming several wallets
emulator, rooted, vpnThe device reported it (device signals)Context, not proof: many honest users run a VPN
reversal_rateReversals are more than 20 % of the user's conversions in the last 30 daysThe wallet entries: offers completed and then charged back
velocity2 or more other requests in the last 24 hoursSplitting a big amount into small ones
young_accountAccount younger than 14 daysHow the cash was earned so fast
first_payoutThe user has no paid request yetEvery first payout is reviewed by a person
destination_sharedAnother account used the same PayPal e-mail, crypto address, bank account or card"Destination also used by" in the drawer
user_flaggedThe user has open fraud flagsConsole → Fraud flags
Signals the app reports can be faked

Device, emulator, root and VPN come from the device itself. A modified app can send anything. Use them to decide what to look at, together with the server-side facts (wallet entries, reversals, shared destinations, account age).

Destination reuse is tracked with a SHA-256 hash of the normalised destination (payoutDestinations, payoutRequests.destinationKey), so the console finds matches without keeping a second copy of the destination.

03Auto-approve

Console → Wallet & payouts → Auto-approve small requests (off by default). A request is auto-approved only when all three are true:

  • auto-approve is on,
  • the amount is at or below Always review requests above (cents) (default 2000),
  • the request has no flag at all. Because every first payout is flagged first_payout, a user's first payout is never auto-approved.

An auto-approved PayPal request is sent at once when PayPal credentials exist. Other methods still need you to pay and mark paid. Start with auto-approve off, review by hand for a few weeks, and only then consider it.

04Before the money reaches the wallet

  • The hold keeps new cash pending for wallet.holdDays (default 14) so provider reversals land before users can cash out (Hold).
  • Big cash credits and every credit of a flagged user wait in the Review queue (fraud.offerwallHoldOverCents, details).
  • The 3.1 protection still applies: signed provider postbacks, de-duplication, App Check, the accounts-per-device limit and the velocity rule (Anti-fraud).

05Your own checks

  • Keep daily and monthly limits that fit your budget; 0 means no limit
  • Look at every flagged request before you approve it
  • Freeze payouts for a user you are investigating (earning continues)
  • Before a crypto payout, check the asset and network; transfers cannot be reversed
  • Reconcile your PayPal, bank and wallet statements with the Business page regularly
  • Apply the identity checks your obligations require before paying (KYC and AML); the app does not verify identities